Oh yes! Thank you for the feedback.
I've added a new version where the `iv` and the `salt` is random.
Maybe a followup question: Because you need both the `iv` and `salt` to decrypt the message is it ok in an E2E scenario to send all three: `iv`, `salt` and the encrypted message?